VMware Cloud Community
VEspin
Contributor
Contributor

Cannot join vCenter server to AD domain

vcenter_domainjoin_error.PNG

When  clicking the join button I receive the above message. I receive the same error message from the HTML5 and Flex clients. I don't know if it has anything to do with it but this vCenter server was linked to another vCenter server's SSO domain. That server is domain joined. I've not had any success finding information about this error. Anyone have any thoughts?

Thanks

0 Kudos
12 Replies
VEspin
Contributor
Contributor

I realized I should have provided more information. This is vCenter 6.7. I just updated to 6.7.0.20100 to see if it resolved the problem but it did not. The error message changed though:

vcenter_domainjoin_error02.PNG

Same in FLEX:

vcenter_domainjoin_error03.PNG

I'm not even sure where to begin looking into this so any suggestions would be appreciated.

0 Kudos
VEspin
Contributor
Contributor

I decided to try to join using the CLI and it worked. I rebooted the server. When I log into the web interface and go to Administration > Configuration > Active Directory Domain it says "The node didn't join any Active Directory." but when I query in the CLI it shows that it is joined to the domain. I'm also able to login with my domain credentials and I was not able to before the CLI domain join.

0 Kudos
NelsonCandela
Enthusiast
Enthusiast

Do you use an internal or external PSC?

0 Kudos
VEspin
Contributor
Contributor

Internal. We're using vCenter Server with an embedded Platform Services Controller.

0 Kudos
a_p_
Leadership
Leadership

... Administration > Configuration > Active Directory Domain it says "The node didn't join any Active Directory."

I saw this too in a customer environment. However, IIRC it's only in the HTML5 client, the Flash client displayed the status correctly.

Please check the setting in the Flash client.

André

0 Kudos
VEspin
Contributor
Contributor

The FLEX client also shows it blank, but a CLI query gives an output like below:

root@vcenter [ ~ ]# /opt/likewise/bin/domainjoin-cli query

Name = vcenter

Domain = domain.ext

Distinguished Name = CN=VCENTER,CN=Computers,DC=domain,DC=ext

2019-01-04 12_18_36-vSphere Web Client.png

0 Kudos
VEspin
Contributor
Contributor

Bumping this in the hopes anyone else has any ideas.

0 Kudos
GayathriS
Expert
Expert

So you are trying to change the domain to which VC belongs to from old to new Domain?

or adding multiple domains ?

regards

Gayathri

0 Kudos
GayathriS
Expert
Expert

Is there anything to do with compatibility:

VMware Knowledge Base

regards

Gayathri

0 Kudos
VEspin
Contributor
Contributor

No compatibility issue, domain functional level is 2008 R2.

0 Kudos
VEspin
Contributor
Contributor

I'm not trying to change domain. I was able to join the domain from CLI, and when I use the CLI to query domain join status it shows that is the case. I'm also able to login with domain credentials where I was not able to before. The only problem I have now is that neither the HTML5 or FLEX clients show that the vCenter server is joined to a domain at all even though it shows that it is in CLI and is otherwise acting as though it is. Seems to be a bug.

0 Kudos
NelsonCandela
Enthusiast
Enthusiast

Hi VEspin,

after you joined the VCSA via CLI, have you tried to dissolve the connection again over CLI and re-try connecting using the GUI within the VCSA? I'm curious if, once the Domain Join has been done successfully before, if a second try would also be fruitful ...

Maybe you're right and it's a bug; yet after checking the big G-search engine I have not been able to identify this problem being documented elsewhere.

BR

NC

0 Kudos